Courseiva
Operations and MaintenancehardMultiple SelectObjective-mapped

PAS-C01 Operations and Maintenance Practice Question

Which TWO actions should be taken to securely manage database credentials for an SAP system running on Amazon RDS for Oracle? (Choose 2)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use IAM database authentication to manage access without passwords.

Options C and D are correct. IAM database authentication (C) allows you to use IAM users and roles to authenticate to your RDS database, eliminating the need for passwords. AWS Secrets Manager (D) securely stores and automatically rotates database credentials, which is a best practice for managing secrets. Option A is incorrect because storing credentials as an S3 object lacks native rotation and is less secure than dedicated secrets management services. Option B is incorrect: although Systems Manager Parameter Store can store secure strings, it does not natively rotate RDS credentials. Option E is incorrect because AWS CloudHSM is a hardware security module for key generation and encryption, not for storing and rotating passwords.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Store the credentials as an S3 object with server-side encryption.

    Why it's wrong here

    S3 is not designed for credential management and rotation.

  • Use AWS Systems Manager Parameter Store with a secure string parameter.

    Why it's wrong here

    Parameter Store can store passwords but does not natively rotate RDS credentials.

  • Use IAM database authentication to manage access without passwords.

    Why this is correct

    IAM database authentication allows IAM users to connect using an authentication token.

  • Use AWS Secrets Manager to store and automatically rotate the database passwords.

    Why this is correct

    Secrets Manager manages secrets and can rotate RDS credentials automatically.

  • Store the credentials in AWS CloudHSM.

    Why it's wrong here

    CloudHSM provides hardware security modules for key storage, not credential management.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every PAS-C01 question from scratch — 1,616 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PAS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PAS-C01 exam.